CRITICAL

CVE-2018-16858

CVSS v3

9.8

CRITICAL

EPSS Score

92.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

Technical details

Published
3/25/2019

Frequently asked questions

What is CVE-2018-16858?

It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

Is CVE-2018-16858 actively exploited?

Active exploitation of CVE-2018-16858 has not been confirmed. The EPSS score is 92.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2018-16858?

CVE-2018-16858 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2018-16858 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.